CHEAT SHEET · CISA

CISA Cheat Sheet.
The night-before summary, built like the exam.

Weighted to the current exam outline·15-minute scan
By Vincent Ruan, EA, CFP®Published July 21, 2026
Drill weak spots →

CISA Exam Logistics At-a-Glance

ItemDetail
Format150 multiple-choice questions
Testing time240 minutes (4 hours)
Passing scoreScaled score of 450 or higher (scale runs 200-800)
Fee (ISACA member)US$575.00
Fee (non-member)US$760.00
Testing vendorPSI (in-person test centers or remote online proctoring)
Test center availabilityMore than 1,300 PSI locations worldwide
Eligibility window6 months from date of registration to sit the exam
Certification application window5 years from passing to apply for certification

Why the Scaled Score Matters

  • ISACA reports results on a 200-800 scaled range rather than raw percent correct, so a 450 is not "56%" in any simple sense — treat it as a pass/fail threshold, not a percentage target.
  • Because scaling normalizes difficulty across exam forms, don't try to reverse-engineer how many raw questions you can miss; focus study time proportionally to domain weight instead.

The Five CISA Content Domains

The exam content outline that took effect 1 August 2024 organizes all tested material into five job practice domains. Memorize the order and weights — weight roughly predicts how many of the 150 questions come from each domain.

  1. Domain 1 — Information Systems Auditing Process (18%)
  2. Domain 2 — Governance and Management of IT (18%)
  3. Domain 3 — Information Systems Acquisition, Development and Implementation (12%)
  4. Domain 4 — Information Systems Operations and Business Resilience (26%)
  5. Domain 5 — Protection of Information Assets (26%)

The Domain-Weight Trap

  • Domains 4 and 5 together make up 52% of the exam — over half your questions come from just two domains, so under-studying operations/resilience and information-asset protection is the single biggest scoring risk.
  • Domain 3 (systems acquisition/development) has the lowest weight at 12%, but candidates from a pure-audit background often over-invest here relative to its payoff — budget study time by weight, not by comfort level.
  • Domains 1 and 2 are tied at 18% each; many candidates assume the "process" domain (1) is the biggest because it's listed first — it is not.

Key Terms and Concepts to Memorize

  • IS Audit Process — risk-based audit planning, evidence gathering, audit standards/guidelines, and communicating results to stakeholders.
  • IT Governance — the difference between governance (setting direction/oversight) and management (day-to-day execution); IT strategy alignment with enterprise goals; enterprise risk management frameworks.
  • SDLC controls — control points across the systems development life cycle, project governance, change management, and post-implementation review.
  • Business resilience — business continuity planning (BCP) vs. disaster recovery planning (DRP), RTO/RPO concepts, incident management, and IT operations controls (job scheduling, capacity, problem management).
  • Information asset protection — security architecture, identity and access management, network/endpoint security, encryption fundamentals, and data classification/privacy controls.
  • Auditor mindset questions — CISA scenario questions frequently reward the answer that reflects what an auditor should recommend or do first, not necessarily the most technically correct security fix.

Common Gotchas and Traps

  • ISACA exam questions often present several technically true answers — the correct choice is the best or first action from an audit/risk perspective, not merely a valid one.
  • Watch for questions that test whether you know an auditor's role is independent evaluation and reporting, not implementing fixes — answers that have the auditor "fix" a control are usually traps.
  • Don't confuse governance-level concerns (policy, oversight, risk appetite) with management-level or operational-level concerns; ISACA question stems often hinge on which organizational level should act.
  • The revised exam content outline places increased emphasis on risk, security, and controls tied to disruptive/emerging technologies — don't assume the exam is only about legacy IT audit topics.
  • Remember the CISA credential itself requires ongoing Continuing Professional Education (CPE) after certification — passing the exam is the first step, not the end state, and this distinction sometimes appears in eligibility-focused review questions.

Night-Before Checklist

  • Confirm your testing modality (in-person PSI test center vs. remote online proctoring) and verify the exact appointment time and location or system requirements.
  • Bring required government-issued photo ID matching your registration name exactly.
  • Review the domain weight table one final time — mentally re-rank Domains 4 and 5 as your highest-yield review areas since together they cover 52% of content.
  • Do a light pass on terminology you still hesitate on: governance vs. management, BCP vs. DRP, RTO vs. RPO, and audit independence principles.
  • Plan for the full 240-minute session — eat beforehand and avoid over-caffeinating; there is no traditional scheduled break built into a fixed-length CBT session, so pace yourself across all 150 questions.
  • Remind yourself of the pass threshold: a scaled score of 450+ is the goal — don't let anxiety over any single hard question derail your pacing on the rest.
  • Reconfirm your plan for after the exam: you'll have 5 years from a passing result to formally apply for the CISA certification, so keep your exam confirmation/results paperwork accessible.

Frequently asked questions

How much does the CISA exam cost, and how long is my registration valid?

The CISA exam registration fee is US$575.00 for ISACA members and US$760.00 for non-members. Once you register, your exam eligibility period is 6 months from the date of registration, so you should schedule and sit the exam within that window. If you don't test in time, you would need to re-register. Because the member fee is US$185 lower than the non-member fee, it's worth comparing the cost of ISACA membership against that gap before you pay.

How is the CISA exam structured, and what score do I need to pass?

The CISA exam consists of 150 questions and has a total testing time of 240 minutes (4 hours), which works out to an average of about 1.6 minutes per question if you use the full time. It is built around 5 job practice domains, and a scaled score of 450 or higher is required to pass. The 450 figure is a scaled score, not a raw percentage or a count of correct answers, so you can't simply target "X questions right" — pace yourself across all 150 items and don't over-invest in any single question.

Which CISA domains should I study hardest?

The five content domains are the Information Systems Auditing Process, Governance and Management of IT, Information Systems Acquisition/Development and Implementation, Information Systems Operations and Business Resilience, and Protection of Information Assets. Their weights are not equal: Domain 1 (18%), Domain 2 (18%), Domain 3 (12%), Domain 4 (26%), and Domain 5 (26%). Domains 4 and 5 together account for 52% of the exam content, so more than half of your score depends on IS operations, business resilience, and protection of information assets. A practical study plan weights the largest share of preparation time toward Domains 4 and 5, since Domain 3 alone (12%) carries less than half the weight of either of them.

After I pass, how long do I have to apply for the CISA certification, and what keeps it active?

Passing the exam and holding the certification are two separate steps. Candidates have five years from the date of passing the exam to apply for CISA certification, so you don't have to file the application immediately — but if you let all five years lapse without applying, your passing result no longer qualifies you. Once certified, professionals must adhere to ISACA's Continuing Professional Education (CPE) Policy to retain the credential, meaning the certification is maintained through ongoing CPE rather than being a one-time achievement. Plan to both submit your application within the five-year window and build a habit of tracking CPE hours from the start.

Sources

  1. 1.CISA Exam Content OutlineISACA (accessed Jul 18, 2026)
  2. 2.CISA Certification OverviewISACA (accessed Jul 18, 2026)
  3. 3.Certification Exam Candidate GuidesISACA (accessed Jul 18, 2026)
  4. 4.ISACA's CISA Exam Updated to Reflect Innovations and Evolving Technologies (Press Release, 2024)ISACA (accessed Jul 18, 2026)